Jr. Cyber Security Analyst - South Dakota

P3S Corporation
Ellsworth Air Force Base, SD, United States
26 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Working hours
Regular working hours
Job source

Tech stack

Active Directory Audit Trail Cyber Security Decision Support Systems Linux Security Information and Event Management Automated Information System (AIS) Nessus Plan of Action and Milestones Vulnerability Analysis

Job description

The Jr. Cyber Security Analyst supports enterprise cybersecurity engineering and Risk Management Framework (RMF) lifecycle activities for Department of the Air Force Financial Management systems within the FM Authorizing Official (AO) boundary. Working with senior cybersecurity analysts, ISSOs/ISSMs, system owners, Program Management Offices, engineers, and Government stakeholders, the analyst supports authorization artifacts, vulnerability and risk management, continuous monitoring, remediation tracking, and risk-informed decision support., * Assist with the full RMF lifecycle, including security control selection, implementation, validation, continuous monitoring, and authorization sustainment for assigned FM systems.

  • Develop, update, and maintain authorization artifacts such as System Security Plans (SSPs), Risk Assessment Reports (RARs), Plans of Action & Milestones (POA&Ms), control documentation, and continuous-monitoring records in eMASS and ITIPS.
  • Support vulnerability assessments, risk analysis, and development of mitigation strategies; coordinate and track remediation with system owners, PMOs, system administrators, and engineering teams.
  • Track and report vulnerability trends, remediation status, POA&M closure progress, overdue items, and risk trends for leadership review.
  • Assist in preparing complete A&A decision staffing packages containing risk analysis, control summaries, mission impact, and recommendations supporting ATO, ATO with Conditions, or Denial decisions.
  • Support security control assessments and prepare findings documenting gaps, weaknesses, associated risk levels, and recommended remediation strategies.
  • Maintain FM system inventory/boundary information, including points of contact, authorization status, and ATO expiration information.
  • Assist with cybersecurity policy, SOP, template, checklist, status-report, briefing, and presentation updates for Government review.
  • Support DISA STIG implementation/validation, vulnerability-remediation coordination, configuration-baseline compliance, and applicable IAVA/TCNO/security-directive tracking.
  • Review security alerts, audit logs, vulnerability data, and system events; support cybersecurity incident reporting, documentation, escalation, and investigation support.
  • Facilitate communication among system owners, security personnel, PMOs, and the FM AO/AODR to resolve information-assurance issues and support governance forums.
  • Prepare accurate, timely, controlled, and Section 508-compliant cybersecurity documentation and deliverables., * Obtain and maintain the Government-required suitability, access, and security determinations applicable to assigned duties and comply with the DD254 and local installation requirements.
  • Maintain the minimum NACI/Entrance NACI required for personnel using unclassified Government Automated Information Systems (AIS), including email. Personnel with root access to operate, modify, or maintain a Government system must meet the trustworthiness/background-investigation requirement specified by the PWS/DD254.
  • Complete Air Force-mandated Information Assurance Awareness Training before access to Government computing resources and maintain required DD Form 2875 System Authorization Access Request documentation.
  • Obtain and properly display required CAC, Restricted Area Badge, contractor identification, and other installation credentials as applicable.
  • Immediately report known or suspected security violations or incidents and assist Government security-related inquiries or investigations as directed.
  • Protect Personally Identifiable Information (PII) in accordance with NIST SP 800-122 and comply with the Privacy Act, applicable Air Force security directives, Government-resource restrictions, and consent-to-monitoring requirements.
  • Complete the required Contractor Employee Non-Disclosure Agreement and use Government-furnished systems and resources for authorized official business only.

Requirements

  • RMF and A&A fundamentals; NIST SP 800-53; DoDI 8510.01; Air Force cybersecurity policy; DISA STIG concepts.
  • eMASS and ITIPS authorization-artifact management.
  • Vulnerability assessment, risk analysis, mitigation planning, POA&M management, and continuous monitoring.
  • Familiarity with approved vulnerability/security monitoring tools such as ACAS/Nessus and comparable enterprise tools.
  • Working knowledge of Windows/Linux, Active Directory, enterprise infrastructure, and configuration-baseline concepts., * Federal, DoD, or Air Force cybersecurity/RMF support.
  • Air Force Financial Management, AFFSO, SAF/FM, AFIMSC, or comparable enterprise program environments.
  • Experience preparing cybersecurity compliance reports, assessment findings, risk summaries, and authorization documentation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

5:02 min

Reviewing deployment strategies and monitoring guidelines

Aleksandr Kalikov · LIVE

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · World Congress 2026 Europe

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all